Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52671
Total
4197
Critical
15603
High
15291
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-57364 | MEDIUM | 6.5 | Improper Validation of Specified Quantity in Input vulnerability in WPDeveloper Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More better-payment allows Accessing Functionality … | Jul 13, 2026 |
| CVE-2026-57363 | HIGH | 7.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot chatbot allows Stored XSS.This issue affects ChatBot: from n/a through <= … | Jul 13, 2026 |
| CVE-2026-49876 | MEDIUM | 6.5 | Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs. A vulnerability in Apache … | Jul 13, 2026 |
| CVE-2026-41041 | CRITICAL | 9.1 | URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 before 1.2.1. Users are recommended to upgrade … | Jul 13, 2026 |
| CVE-2026-22103 | UNKNOWN | — | The NPC start endpoint on the web server at port 8090 is vulnerable to command injection. | Jul 13, 2026 |
| CVE-2026-22102 | UNKNOWN | — | A POST request sent to a specific webserver endpoint can be used to write to arbitrary file locations. The endpoint accepts the filename parameter in … | Jul 13, 2026 |
| CVE-2026-22100 | UNKNOWN | — | The OCPP DataTransfer message `ReserveLogin` is vulnerable to command injection. By manipulating the data value, arbitrary OS commands can be executed as root. | Jul 13, 2026 |
| CVE-2026-22099 | UNKNOWN | — | The charging station does not require authentication for Bluetooth commands to perform actions. The functionality exposed includes sensitive information leakage, triggering reboots, or pushing a … | Jul 13, 2026 |
| CVE-2026-22098 | UNKNOWN | — | Various sensitive information such as passwords and charging card UIDs are written to log files. | Jul 13, 2026 |
| CVE-2026-22097 | UNKNOWN | — | The firmware update mechanism does not include cryptographic signature validation. This allows anyone with access to the firmware update capability to upload arbitrary files which … | Jul 13, 2026 |
| CVE-2026-22096 | UNKNOWN | — | The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such as configured passwords, or uploading files through different … | Jul 13, 2026 |
| CVE-2026-22095 | UNKNOWN | — | The network diagnosis endpoint on the web server at port 8090 is vulnerable to command injection. | Jul 13, 2026 |
| CVE-2026-22093 | UNKNOWN | — | The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided by the server. This allows an attacker on … | Jul 13, 2026 |
| CVE-2026-15557 | HIGH | 7.3 | A weakness has been identified in waooAI waoowaoo up to 0.4.1. Affected by this vulnerability is the function getInternalTaskSession/getAuthSession/requireUserAuth/requireProjectAuth/requireProjectAuthLight in the library src/lib/api-auth.ts of the … | Jul 13, 2026 |
| CVE-2026-15548 | HIGH | 8.8 | A security vulnerability has been detected in Shibby Tomato up to 1.28.0000. This vulnerability affects the function sub_407220 of the file /usr/sbin/httpd of the component … | Jul 13, 2026 |
| CVE-2026-14846 | UNKNOWN | — | In version 8.2.1 of PrestaShop, there is a vulnerability relating to the incorrect sanitisation of elements, caused by inadequate validation of the ‘Alias’ parameter in … | Jul 13, 2026 |
| CVE-2026-13014 | UNKNOWN | — | A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute arbitrary code and arbitrarily overwrite writable application files—including … | Jul 13, 2026 |
| CVE-2026-9708 | MEDIUM | 4.9 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target … | Jul 13, 2026 |
| CVE-2026-9597 | MEDIUM | 5.4 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token … | Jul 13, 2026 |
| CVE-2026-9571 | MEDIUM | 5.9 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivated … | Jul 13, 2026 |
| CVE-2026-6850 | MEDIUM | 6.5 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of message attachment field values, which allows … | Jul 13, 2026 |
| CVE-2026-62143 | UNKNOWN | — | A Server-Side Request Forgery (SSRF) protection bypass existed in the html_to_markdown expansion module of misp-modules. The module attempts to prevent requests to loopback, private, link-local, … | Jul 13, 2026 |
| CVE-2026-15574 | HIGH | 7.5 | A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorization headers and full chat payloads, which may contain personally … | Jul 13, 2026 |
| CVE-2026-15547 | MEDIUM | 6.3 | A weakness has been identified in Shibby Tomato up to 1.28.0000. This affects the function sub_2D048 of the component CIFS Mount Handler. Executing a manipulation … | Jul 13, 2026 |
| CVE-2026-15546 | MEDIUM | 6.3 | A security flaw has been discovered in Shibby Tomato up to 1.28.0000. Affected by this issue is the function sub_2D568 of the component start_jffs2. Performing … | Jul 13, 2026 |